Vulnerabilities in Citrix Workspace app and Receiver for Windows

Vulnerabilities in Citrix Workspace app and Receiver for Windows

book

Article ID: CTX275460

calendar_today

Updated On:

Description

Description of Problem

Vulnerabilities have been identified in Citrix Workspace app and Citrix Receiver for Windows that could result in a local user escalating their privilege level to administrator during the uninstallation process.

The issues have the following identifiers:

  • CVE-2020-13884

  • CVE-2020-13885 

These vulnerabilities affect supported versions of Citrix Workspace app for Windows before 1912 and supported versions of Citrix Receiver for Windows.

These vulnerabilities do not affect Citrix Workspace app and Receiver on any other platforms.


What Customers Should Do

Citrix strongly recommends that customers upgrade to Citrix Workspace app version 1912 or later. Customers using Citrix Receiver are strongly recommended to upgrade to Citrix Workspace app. Customers using Citrix Receiver 4.9 for Windows LTSR may alternatively choose to upgrade to Citrix Receiver 4.9.9002 for Windows LTSR Cumulative Update 9 or later to obtain the fixes.

Customers should upgrade via Auto Update, or by running the installer. Customers should not uninstall the previous version of Citrix Workspace app or Citrix Receiver prior to performing the update. 

The latest version of Citrix Workspace app for Windows is available from the following Citrix website location: 

https://www.citrix.com/downloads/workspace-app/

The latest version of Citrix Workspace app for Windows LTSR is available from the following Citrix website location:

https://www.citrix.com/downloads/workspace-app/workspace-app-for-windows-long-term-service-release/

The latest version of Citrix Receiver for Windows LTSR is available from the following Citrix website location:

https://www.citrix.com/downloads/citrix-receiver/windows-ltsr/


Acknowledgements

Citrix would like to thank Andrew Hess for working with us to protect Citrix customers.


What Citrix Is Doing

Citrix is notifying customers and channel partners about this potential security issue. This article is also available from the Citrix Knowledge Center at  http://support.citrix.com/.


Obtaining Support on This Issue

If you require technical assistance with this issue, please contact Citrix Technical Support. Contact details for Citrix Technical Support are available at  https://www.citrix.com/support/open-a-support-case.html


Reporting Security Vulnerabilities

Citrix welcomes input regarding the security of its products and considers any and all potential vulnerabilities seriously. For details on our vulnerability response process and guidance on how to report security-related issues to Citrix, please visit the Citrix Trust Center at https://www.citrix.com/about/trust-center/vulnerability-process.html.


Changelog

Date Change
2020-06-11Initial Publication
2020-06-11Updated CWA LTSR URL
2020-06-22Receiver 4.9.9002 LTSR CU9 released